Skip to main content
Questionnaires let you collect structured written responses from vendors — asking specific questions about their security program, controls, or practices. Unlike artifact collection (which relies on documents), questionnaires put questions directly to the vendor and capture their answers as a response artifact. Questionnaires are managed in Settings → Questionnaires. Creating and editing questionnaires requires Admin or Program Manager access.

When to Use Questionnaires

Questionnaires are useful when:
  • A vendor doesn’t have formal audit reports and needs to self-attest to their security practices
  • You want to ask specific questions not covered by standard artifact types
  • Controls remain unvalidated after artifact review and you need targeted clarification
  • Your compliance program requires vendors to answer specific questions in writing

Creating a Questionnaire

1

Navigate to Settings → Questionnaires

Click Add questionnaire to create a new one.
2

Choose how to build it

  • Import — use the provided CSV template to define questions in bulk
  • Create — build the questionnaire question by question in the interface
3

Name it

Use a descriptive name — this is visible to vendors when they receive an assessment request containing the questionnaire.
4

Configure the response method

Choose how responses will be collected:Answer with AI — Artifact Intelligence will attempt to answer the questions automatically using available documents and vendor artifacts. Faster, no vendor effort required. You can still follow up with the vendor if clarification is needed.Require vendor response — questions are sent directly to the vendor during interactive assessments. The vendor answers in writing through the collection portal.
5

Set the default scope (optional)

Toggle Enable for every relationship to apply the questionnaire to all vendor relationships by default. This default can be overridden at the relationship level.

Managing Questionnaire Scope

Organization Level

Questionnaires enabled at the org level apply to all new assessments by default. Go to Settings → Questionnaires to enable, disable, or edit questionnaires globally.

Relationship Level

To include or exclude a questionnaire for a specific vendor:
  1. Open the vendor relationship
  2. Open the Relationship configuration dialog (gear icon) and go to Context → Supplemental questionnaires
  3. Use the slide toggles to turn individual questionnaires on or off
  4. Use Restore organization defaults to revert to org-level settings
Removing a questionnaire from a relationship excludes it from future assessments and hides responses in the Risk Analysis tab. Previously collected responses are retained.

Questionnaire Results in Assessments

When a vendor responds to a questionnaire, the response is:
  • Stored as a Questionnaire artifact in the Artifacts tab
  • Displayed in the Risk Analysis tab as a new risk dimension alongside your existing control domains
  • Analyzed by Artifact Intelligence to map answers to controls where applicable
Questionnaire responses carry Limited assurance — they’re self-attested by the vendor. For high-risk controls, validate questionnaire responses against documentary evidence where possible.

Follow-Up Questionnaires

Follow-up questionnaires are automatically generated when controls remain unvalidated after artifact review. They target the specific gaps identified in the assessment rather than being a general questionnaire. You can configure follow-up behavior at three levels:
  • Always ask before following up — VISO TRUST prompts you to review and decide whether to send a follow-up
  • Conditional based on residual risk — automatically send a follow-up when residual risk is at or above a threshold (e.g., Medium)
  • Use assessment concierge service — VISO TRUST manages the follow-up on your behalf
The follow-up response window is configurable (7, 14, 30, 60, or 90 days; 7 by default). VISO TRUST auditors validate the responses (when the AI Assessment + Auditor Review method is configured) and update the assessment findings. See Assessment Settings to configure follow-up defaults.

One-Off Questionnaires

You can send a questionnaire as part of any individual collection request, even if it isn’t configured as a default. When starting a collection request, select Request manual response and choose the questionnaire to include. This lets you send targeted questionnaires to specific vendors without changing org or relationship defaults.